Identity Management Framework
Delivering Value for Business
By Srinivasan Vanamali, CISA, CISSP
With the advent of web-enabled technologies, extranets for partners and federated networks for business units, organizations are moving away from a closed business model to a more open model. This has resulted in complexity dealing with users and managing their access to systems. There is also increased risk due to ineffective controls in managing user identities, establishing trust, enabling privacy, and complying with legal and regulatory requirements. Identity management (IM) deals with these risks. Identity management, in a nutshell, is a convergence of business processes and technology to provide security, trust and privacy by identifying users and authorizing access to identity-based systems, information resources and applications.
Identity management is often perceived to be the panacea for all issues related to an open model, identity-based system. However, more and more organizations deploy identity management solutions from a tactical perspective—isolated technology initiatives to solve technical issues or deal with compliance requirements—rather than from a strategic point of view, which is business-driven and outcome-based. As pointed out in Burton Group analyst research, "…historically, enterprises have made attempts to treat the symptoms of the identity management problem with point solutions."
It is further noted in the research, "Many enterprises make the mistake of rushing to implement directories, security systems and other IM components before they evaluate how they’re storing, managing and distributing identity information."
This has resulted in:
- Fragmented point solutions
- Failure to leverage existing investments and infrastructure
- Dilution of identity management initiatives over time
- Increasingly difficult funding for further initiatives
For identity management to thrive organizationwide and deliver business value, it is important to establish a framework that acts as a term of reference for all identity management initiatives.
Critically important in the emerging model is the ability to integrate business processes and technology to provide fine levels of granularity in terms of linking people to systems and services. One of the key objectives of identity management is to centralize and standardize this process so that it is provided consistently as a common service across the organization.
Identity management is comprised of many components that provide a collective and common infrastructure, including directory services, authentication services (validating who the user is) and authorization services (ensuring the user has appropriate privileges to access systems based on a personalized profile). It also includes user-management capabilities, such as user provisioning and deprovisioning.
Approach to Identity Management
Under the prevailing business environment where IT budgets are ever shrinking, organizations are reluctant to spend on new initiatives that will solve only technical problems. Today’s approach is “business-driven IT,” where IT solutions go beyond solving technical issues to enabling the business. Identity management initiatives reflect the fundamental change in the role of IT within organizations. The premise is that identity management solutions deliver real business value with tangible benefits. This occurs by improving responsiveness to the business with solutions like delegated and self-service administration, which reduces the reliance on support organizations. Identity management also delivers a measurable return on investment by means of reducing cost and improving productivity.
For example, an automated workflow system could streamline the user provisioning process and eliminate the need for a number of silo administrators managing different systems and applications. Users self-managing their accounts, resetting their passwords and unlocking their accounts through a portal will also improve productivity.
Why a Framework?
As further noted in the Burton Group research, "…most of today’s IM infrastructures are ad hocracies, built one application or system at a time, rather than created within an enterprisewide framework. The result is a spider web of overlapping repositories, inconsistent policy frameworks and IM process discontinuities."
To address this scope and complexity, a simple model is required—a framework that can be used to discuss the major business issues and how to deal with them effectively and efficiently. A framework will serve as a basis for vital understanding between business management and technical managers on all identity management initiatives.
Key Components of the Identity Management Framework
- Security Vision
Organizations must have an executive-sponsored security strategy based on current business and IT strategy. Identity management initiatives must closely align with the organization’s security initiatives. - Identity Management Strategy
An identity management strategy is a key component of the framework and must align closely with the organization’s business and IT strategy. - Policies and Standards
The framework must outline a set of policies for identity management covering a range from organizationwide to system-specific. Examples include defining minimum authentication levels and acceptable levels of encryption. - Identity Management Architecture
Organizations should have an enterprise architecture encompassing the security architecture. The identity management architecture must align with the security architecture and identify the key components of identity management. - Identity Management Specifications
The detailed specifications guide technology choices based on required functionality and must cover evaluation criteria for acquiring or integrating identity management solutions.
Identity Management Road Map
Defining a road map is a critical component of the framework. One of the challenges often faced by organizations is where to start and how to go about delivering a solution. A typical road map must identify practical steps to deploy and integrate identity management components in line with the organization’s specifications, architecture, policies, and standards.
This approach is based on a high priority but a short-term strategy to address a business-critical issue, which will improve the user experience and productivity.
Conclusion
While identity management solutions are becoming a popular response to security challenges, organizations must consider how to ensure benefits and value to the business. Identity management initiatives are often diluted over time as organizations fail to leverage their existing technology and intellectual property investments, and instead reinvent the wheel. The identity management framework provides a basis for successful, business-driven and clearly understood identity management.